CVE-2026-45504
HIGHMicrosoft Exchange Server Elevation of Privilege Vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-45504. PoCs published by hawktrace.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2026-45504, which targets a file read vulnerability in Microsoft Exchange via SSRF. The exploit authenticates to OWA, creates a malicious attachment, and reads arbitrary files from the target system.
Description
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Exploits (1)
This repository contains a functional Python exploit for CVE-2026-45504, which targets a file read vulnerability in Microsoft Exchange via SSRF. The exploit authenticates to OWA, creates a malicious attachment, and reads arbitrary files from the target system.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H